PT-2024-16395 · Tongda Oa · Tongda Oa
Lvzc
·
Published
2024-10-31
·
Updated
2024-11-04
·
CVE-2024-10598
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tongda OA versions 11.2 through 11.6
Description
A critical vulnerability was found in Tongda OA, affecting unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave Handler. The manipulation leads to improper authorization, allowing remote attacks. The exploit has been disclosed to the public and may be used.
Recommendations
For Tongda OA versions 11.2 through 11.6, update to the latest patched version immediately to mitigate risks. As a temporary workaround, consider restricting access to the Annual Leave Handler component until a patch is available. Additionally, audit logs for signs of exploit.
Exploit
Fix
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tongda Oa